私有仓库拉取失败主因是ssh连接未通或https凭据未加载,必须先确保ssh -t git@your-host-alias成功返回welcome信息;否则composer根本不会进入认证阶段,所有后续操作均失效。

私有仓库拉取失败,90% 不是权限或网络问题,而是 Composer 根本没走到 Git 认证那步——SSH 连接压根没建立,或者 HTTPS 凭据根本没被读取。
ssh -T 测试不通,Composer 必然失败
所有后续操作都依赖这一步:执行 ssh -T git@your-host-alias 必须返回 welcome 信息。如果卡住、报 The authenticity of host 'xxx' can't be established 或 Permission denied (publickey),Composer 就不会继续往下走。
-
The authenticity of host 'xxx' can't be established:首次连接,需手动确认 host key;可临时用ssh -o StrictHostKeyChecking=no -T git@your-host-alias(仅限可信内网),或把目标服务器 public key 追加到~/.ssh/known_hosts -
Permission denied (publickey):检查~/.ssh/config中的Host名是否与composer.json里 URL 的主机部分**逐字一致**(例如 URL 是git@10.0.1.5:group/repo.git,Host行就必须写10.0.1.5,不能写git.internal) - 运行
ssh-add -l看输出是否为空;为空说明 agent 没启动或密钥没加载,执行ssh-add ~/.ssh/id_ed25519手动加载
composer.json 的 repositories 配置必须严格合规
写错一个字符,Composer 就会静默跳过你的私有源,直接去 packagist.org 查——然后报 “Could not find package” 或 “repository '' not found”。
围绕关键发现、作用机制、临床相关性及研究局限性展开讨论。适用于撰写或优化任何生物医学论文的“讨论(Discussion)”部分——包括结果解读、与既往文献关联、阐释意外发现、界定研究局限性,以及撰写结论。当用户输入以下任一指令时也会自动触发该功能: - “write my discussion” - “help me discuss my findings” - “how do I compare to prior studies” - “write the limitations par
-
type字段必须显式写"vcs",不能省略、不能写"git"或"package" -
url必须是完整 SSH 格式(如git@gitlab-company:topgroup/subgroup/project.git)或 HTTPS +.git后缀(如https://gitlab.example.com/org/pkg.git);网页地址(不带.git)会被忽略 - SSH 地址中的主机名必须和
~/.ssh/config的Host别名完全一致;写成git@github.com:user/repo.git却配了Host github-personal,Git 就不会用你配的密钥 - GitLab 子组嵌套路径对斜杠敏感:
HostName只能写真实域名(如gitlab.example.com),不能带路径(如gitlab.example.com/topgroup),否则 SSH 解析失败,Composer 报空 repository 名
HTTPS 方式卡在 “could not read Username” 怎么办
这不是密码输错了,而是 git 凭据管理器没准备好——Composer 调用 git clone 时不会弹窗,也不会读终端输入,直接失败。
- 执行
git config --global credential.helper store,然后手动跑一次git clone https://user:token@gitlab.example.com/org/pkg.git(注意是完整 URL,结尾带.git),git 会把凭据存进~/.git-credentials - GitHub/GitLab 的 token 必须含
repo(GitHub)或read_repository(GitLab)权限;token 别硬塞进composer.json,也别提交到 Git - 若用
auth.json,必须放在~/.composer/auth.json(不是项目根目录),且权限设为600;内容格式必须严格,域名大小写、协议前缀都不能错(如"gitlab.example.com"≠"GitLab.example.com")
镜像源和私有源顺序搞反了
很多人在 composer.json 里同时写了私有源和镜像,结果 Composer 先去镜像查——而镜像没有你的私有包,直接报 404。
- 私有源必须放在
repositories数组最前面;镜像源(如阿里云)放后面 - 镜像 URL 必须带末尾斜杠:
https://mirrors.aliyun.com/composer/✅,https://mirrors.aliyun.com/composer❌(少斜杠会导致拼出/packages.json时 404) - CI/CD 环境(如 GitHub Actions)默认不继承本地镜像配置,必须在 workflow 里显式设置,或通过
COMPOSER_AUTH注入凭据
最常被忽略的一点:改完 SSH 配置或 auth.json 后,不删 vendor/ 和 composer.lock 就重试,旧 lock 文件仍会沿用之前解析出的错误地址——必须清掉再 composer install --prefer-source 才能真正验证新配置是否生效。










